PT-2021-23808 · Zoho · Zoho Manageengine Supportcenter Plus

Published

2021-11-30

·

Updated

2022-04-27

·

CVE-2021-43296

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine SupportCenter Plus versions prior to 11016
Description The issue is related to a Server-Side Request Forgery (SSRF) attack in the ActionExecutor. This type of attack allows an attacker to trick the server into making requests to unintended locations, potentially leading to unauthorized access or data exposure.
Recommendations For versions prior to 11016, update to version 11016 or later to resolve the issue. As a temporary workaround, consider restricting access to the ActionExecutor to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43296

Affected Products

Zoho Manageengine Supportcenter Plus